mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH 0/6] fs: ubootvarfs: harden parser
@ 2026-10-02 11:40 Ahmad Fatoum
  2026-10-02 11:40 ` [PATCH 1/6] fs: skip directory entries whose name does not fit struct dirent Ahmad Fatoum
                   ` (5 more replies)
  0 siblings, 6 replies; 7+ messages in thread
From: Ahmad Fatoum @ 2026-10-02 11:40 UTC (permalink / raw)
  To: barebox; +Cc: Ahmad Fatoum

Fix a number of issues in our U-Boot env support, mostly unearthed by
fuzzing with some LLM assistance.

Ahmad Fatoum (6):
  fs: skip directory entries whose name does not fit struct dirent
  fs: reject negative lengths in ftruncate()
  fs: ubootvarfs: range-check the new size in truncate
  fs: ubootvarfs: do not form pointers past the end of the environment
  fs: ubootvarfs: reject variable names containing '='
  fs: ubootvarfs: handle removal of variables that are still open

 fs/fs.c         |  8 ++++++++
 fs/ubootvarfs.c | 36 ++++++++++++++++++++++++++++--------
 2 files changed, 36 insertions(+), 8 deletions(-)

-- 
2.47.3




^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-02 13:33 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 11:40 [PATCH 0/6] fs: ubootvarfs: harden parser Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 1/6] fs: skip directory entries whose name does not fit struct dirent Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 2/6] fs: reject negative lengths in ftruncate() Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 3/6] fs: ubootvarfs: range-check the new size in truncate Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 4/6] fs: ubootvarfs: do not form pointers past the end of the environment Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 5/6] fs: ubootvarfs: reject variable names containing '=' Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 6/6] fs: ubootvarfs: handle removal of variables that are still open Ahmad Fatoum

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox